Re: monitoring iptables

Sandon Van Ness <[email protected]>
Newsgroups gmane.network.mrtg.user
Message-ID <[email protected]>
  I do something similar to just graph ipv6 table with ip6tables. 
Basically using some grep/awk with iptables (with -x so its in bytes). 
Only problem can be is if your tables are flushed often and the values 
are reset.

On 03/25/2014 02:18 PM, Steve Shipway wrote:
>
> IPtables keeps counters against rules, so you can use MRTG to graph 
> this. You would need to write a custom plugin for MRTG that parses the 
> output of ‘iptables –L –n –v’
>
> If your iptables is not on the same host as your MRTG server, then you 
> will need to run the plugin remotely using some method. Either ssh 
> with keys, NRPE with ‘mrtg-nrpe’, or something similar. This sort of 
> information is not normally in SNMP, though you could write your 
> plugin as a ucd-snmpd extension to make it so, though this is getting 
> into a bit advanced coding. I don’t think anyone else has done this 
> previously, though there was an ipchains extension for ucd-snmpd once.
>
> Steve
>
> *Steve Shipway*
>
> [email protected]
>
>
> _______________________________________________
> mrtg mailing list
> [email protected]
> https://lists.oetiker.ch/cgi-bin/listinfo/mrtg
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.